Multiple security vulnerabilities have been identified in req package, which could allow an attacker to exploit unbounded archive/compression extraction and multipart form-data header injection via unescaped.
CVE-2026-49755 (CVSS 7.5 — High): The req package is vulnerable to unbounded archive/compression extraction triggered by response content-type, allowing an attacker with network access capability to exploit this vulnerability.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in req package, which could allow an attacker to exploit unbounded archive/compression extraction and multipart form-data header injection via unescaped.
CVE-2026-49755 (CVSS 7.5 — High): The req package is vulnerable to unbounded archive/compression extraction triggered by response content-type, allowing an attacker with network access capability to exploit this vulnerability.[emaillocker id="1283"]
CVE-2026-49756: The req package is vulnerable to multipart form-data header injection via unescaped, which could allow an attacker with network access capability to inject malicious data. These vulnerabilities collectively present a moderate risk to administrators who have not applied updates. Administrators should review their exposure and apply patches as soon as possible. These vulnerabilities collectively present a moderate risk to administrators who have not applied updates.
These vulnerabilities collectively present a moderate risk to administrators who have not applied updates.
We recommend you to update req to version 0.6.0.
The following reports contain further technical details:
[/emaillocker]